The repository includes tests, a substantial README, a matching source project, and an MIT license. Its only maintainer and zero commits in the last three months make ongoing support uncertain. Pin v1.0.2 and verify maintenance before relying on it.
60%
Total Score
50
83
83
The repository is owned by the same individual namespace as the package, but the backing is a user account rather than an organization, leaving limited visible support capacity.
The package is about 11 months old with three releases, all published within minutes on the same day. That shows initial delivery but not an established maintenance cadence.
There were zero commits and zero active maintainers in the last three months, which is the strongest evidence of uncertain ongoing maintenance.
The repository has only 2 stars, no forks, and no watchers. Popularity is supporting evidence rather than a verdict, but these counts provide little external validation.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, not evidence of a defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.0 | — | — |
laravel/framework Version ^10.0|^11.0|^12.0 | — | — |
livewire/livewire Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.